Service resiliency and backup address different risks
OneDrive and SharePoint are resilient collaboration platforms. Microsoft replicates data, protects the infrastructure and provides useful recovery tools. This lowers the risk of hardware failure or a recent deletion, but it does not automatically guarantee the organization's required retention, an independent recovery point or a measured recovery time for every critical site.
Saying 'Microsoft 365 has no backup' would be inaccurate: Microsoft now offers Microsoft 365 Backup as a separate service, alongside version history, recycle bins and retention policies. The real question is whether the capabilities included with OneDrive and SharePoint satisfy your loss scenarios, RPO, RTO, retention period and administrative-separation requirements. In many organizations, the answer is no without an additional backup policy.
Recovery windows and features vary by licence, tenant configuration and service changes. Validate them in your own environment before placing them in a continuity plan.
What the native protections actually recover
Native mechanisms are an excellent first line of defence. They are fast, integrated and often available to content owners. They are not interchangeable: the recycle bin restores a deleted item, version history rolls back a file, library restore reverses recent operations and Purview retention preserves content according to a lifecycle requirement.
| Mechanism | Documented window or scope | Strength | Limitation to plan for |
|---|---|---|---|
| Version history | Tenant, site or library limits | Fast recovery of a modified file | Versions can expire or be trimmed by policy |
| SharePoint recycle bins | 93 days total across both stages | Deleted files, lists, libraries or sites | Self-service recovery ends after expiry or purge |
| Restore OneDrive | File and folder actions within the last 30 days | Broad rollback after deletion, corruption or ransomware | Files purged from the recycle bin cannot be recovered by this feature |
| Restore a library | Actions within the last 30 days | Bulk rollback for a modern library | Relies on versions and recycle bin; does not restore an entirely deleted library |
| Purview retention | Policy-defined duration | Preservation, disposition and regulatory needs | Not an operational restore workflow optimized for every incident |
| Microsoft 365 Backup | Separate policy from 3 months to 2 years | Recovery points with granular or full restore | Consumption service that must be configured, monitored and tested |
Version history is a collaboration feature, not an independent copy
Version history is valuable after an accidental edit or overwrite. Microsoft lets administrators set limits at the organization, site, library and OneDrive levels. The documented default for new libraries remains a manual limit of 500 major versions without expiry, but existing settings can differ and owners may break inheritance when permitted by the tenant configuration.
Automatic policy can optimize storage, while manual policy can remove versions beyond an age or count. An organization-level change does not necessarily align existing libraries. The presence of a Version history button therefore proves neither minimum retention, uniform coverage nor a copy outside the site's administrative scope.
Inventory exceptions before using versions in an RPO. For critical data, document version count, expiry, who can change settings and the behaviour of non-Office formats or frequently modified files.
Recycle bins and employee departure follow different timelines
For SharePoint Online, Microsoft documents 93 days across the site and site-collection recycle bins. A deleted site is also retained for 93 days before its content and settings are permanently deleted. An API or administrative purge can bypass the normal recycle path, so the recovery plan must include automated deletions and the accounts allowed to purge.
A OneDrive follows another timeline after its user is deleted. Its default retention period is 30 days and can be changed in SharePoint administration. At the end of that period, OneDrive moves to the site-collection recycle bin for 93 days. Assign a manager or secondary owner so a poorly handled departure does not turn personal storage into delayed data loss.
These windows are safety nets, not universal retention. Late discovery, purge, a scope error or incomplete offboarding can exceed them. Backup should continue protecting the account after it leaves active scope for an approved period.
Why Purview, eDiscovery and backup remain complementary
A Purview policy retains or deletes content according to regulatory and information-lifecycle requirements. It can preserve prior content in the Preservation Hold Library and prevent a user deletion from immediately removing a record. That is essential for compliance, but its purpose, scope and search model are not those of rapid operational recovery.
An eDiscovery case addresses a specific investigation or legal matter. Microsoft recommends retention policies and labels for long-term preservation unrelated to a case. Conversely, Microsoft states that OneDrive or SharePoint data existing only in Microsoft 365 Backup is not discoverable with existing eDiscovery tools. Design both plans together without assuming either replaces the other.
The separation is also technical: Microsoft says retention and deletion policies do not automatically flow through to Microsoft 365 Backup. A compliance deletion of live content therefore does not simultaneously remove backup recovery points. This is the kind of logical independence that a version of the live file does not provide.
Start with loss scenarios, not products
A useful strategy starts with the events that must be recovered. For each scenario, record who can cause it, when it might be detected, how much change can be lost and how long operations can wait. A mechanism can be excellent for one deleted file and unsuitable for 800 encrypted sites.
| Scenario | Useful native protection | Question the backup must answer |
|---|---|---|
| File overwritten yesterday | Version history | Does the correct version still exist and who can restore it? |
| Library encrypted 10 days ago | 30-day library restore | Can a healthy point be identified and has restore been tested? |
| Deletion found after several months | Retention if it covered the content | Does backup extend beyond native windows? |
| Account deleted during offboarding | OneDrive retention and secondary owner | Does protection continue after removal from active policy? |
| Malicious administrator or application | Audit, Conditional Access and roles | Do recovery points have separate administration and a grace period? |
| Large-scale ransomware | Native detection and restore | Has the RTO for hundreds of sites been measured? |
| Incorrect Purview policy | Audit and delayed enforcement | Does compliance deletion also affect the backup copy? |
Define RPO, RTO, scope and retention before shopping
RPO is the maximum amount of change the organization accepts losing. RTO is the maximum time before service returns. Set them by class: finance, HR, clinical procedures, project sites, Teams, communication sites and personal OneDrive accounts do not necessarily have the same criticality.
For OneDrive and SharePoint, Microsoft 365 Backup documents a 10-minute RPO for the trailing two weeks and weekly points from 2 to 52 weeks for full restores. Granular file and folder restore provides roughly daily points for the first 14 days, then weekly points. A policy recovery window can be set to 3 months, 6 months, 1 year or 2 years; verify cadence for longer periods when selecting the policy.
Do not confuse RPO with a displayed job frequency. Measure RTO too: declare the incident, obtain rights, find a healthy point, run the restore, validate permissions and return users to work. Microsoft publishes performance expectations, but item count, point type and scope affect the actual result.
Business owner:
Included sites / OneDrive / Teams:
Classification and legal requirements:
Target RPO:
Target RTO:
Retention period:
Oldest required recovery point:
Granular or full restore:
Restore target: original / alternate URL / export:
Authorized administrators:
Test frequency:
Evidence from last test:
Dependencies: Entra ID, groups, apps, metadata, links:Choose native features, Microsoft 365 Backup or a partner solution
Native features may be sufficient for low-criticality data when their windows are accepted, settings are controlled and restore is tested. Microsoft 365 Backup adds a true protection scope, recovery points, granular or full restore and append-only storage. It is consumption billed and remains in the tenant's Microsoft 365 infrastructure and geography.
Microsoft says its storage is append-only to prevent modification of existing points, but backup deletion is not absolutely blocked. A 90-day grace period after offboarding helps recover backups, and multi-admin notifications reduce malicious-action risk. Include that nuance in the immutability assessment.
A partner product can add multitenant management, another destination, longer retention, export or other workloads. The word 'third party' does not guarantee an independent copy: some products use Microsoft 365 Backup Storage. Ask where data resides, who controls keys and deletion, how bulk restore works and how data is recovered when the contract ends.
| Option | Good fit | Validate before purchase |
|---|---|---|
| Native protections only | Low criticality, short window, simple restore | Actual settings, rapid detection and no regulatory dependency |
| Microsoft 365 Backup | Fast integrated recovery at scale | Scope, consumption, window, roles, point cadence and geography |
| Partner on Backup Storage | Enhanced experience with Microsoft performance | Partner-specific features and the same underlying storage domain |
| Independent third-party backup | Required administrative or storage separation | API coverage, fidelity, RTO, export, residency, immutability and exit |
Inventory the tenant with PowerShell before defining scope
A policy that protects 95 percent of sites can miss the one site required for payroll. Start by inventorying active sites, personal OneDrive accounts, deleted sites and version and offboarding settings. Compare that list with protection units actually covered in Microsoft 365 Backup or the vendor console.
The following script is read-only. It uses Microsoft's SharePoint Online Management Shell and exports results for analysis. Replace the tenant name, run it with an appropriate SharePoint role and protect the reports: URLs, owners and volumes are sensitive administrative data.
Import-Module Microsoft.Online.SharePoint.PowerShell -ErrorAction Stop
$tenantName = 'contoso'
$adminUrl = "https://$tenantName-admin.sharepoint.com"
$output = Join-Path $PWD ("M365-recovery-inventory-{0}" -f (Get-Date -Format 'yyyyMMdd-HHmm'))
New-Item -ItemType Directory -Path $output -ErrorAction Stop | Out-Null
Connect-SPOService -Url $adminUrl
$activeSites = @(Get-SPOSite -Limit ALL -IncludePersonalSite $true)
if ($activeSites.Count -eq 0) { throw 'No active site returned; validate tenant and permissions.' }
$deletedSites = @(Get-SPODeletedSite -Limit ALL -IncludePersonalSite)
$tenant = Get-SPOTenant
$activeSites | Select-Object Url,Owner,Template,StorageUsageCurrent,LastContentModifiedDate,LockState |
Export-Csv (Join-Path $output 'active-sites-and-onedrive.csv') -NoTypeInformation -Encoding UTF8
$deletedSites | Select-Object * |
Export-Csv (Join-Path $output 'deleted-sites-and-onedrive.csv') -NoTypeInformation -Encoding UTF8
$tenant | Select-Object OrphanedPersonalSitesRetentionPeriod,EnableAutoExpirationVersionTrim,ExpireVersionsAfterDays,MajorVersionLimit |
Export-Csv (Join-Path $output 'tenant-recovery-settings.csv') -NoTypeInformation -Encoding UTF8
[pscustomobject]@{
CollectedAtUtc = [datetimeoffset]::UtcNow.ToString('o')
ActiveProtectionUnits = $activeSites.Count
DeletedProtectionUnits = $deletedSites.Count
OutputPath = $output
} | Format-ListProtect the backup control plane too
A copy is useful only when an attacker cannot neutralize it with the same compromised account. Use the dedicated Microsoft 365 Backup Administrator role instead of Global Administrator where possible, protect it with phishing-resistant authentication and Conditional Access, and monitor role assignments, policy changes, exclusions and restores.
Separate duties: one person defines scope and another approves retention reductions or mass restore. Maintain a controlled emergency account, document access when Entra ID or the portal is unavailable and send alerts to logging that the backup administrator cannot erase alone.
File backup also does not necessarily recreate all tenant configuration. Inventory groups, permissions, labels, applications, Power Automate flows, SharePoint settings and Teams dependencies. Regular configuration exports reduce rebuild time, even though they do not replace content backup.
Test restore as a production procedure
A green dashboard does not prove recoverability. Every quarter, select a representative file, folder, OneDrive and site. Restore them to a controlled location and verify content, versions, metadata, permissions, links and elapsed time. For in-place recovery, document what happens to changes created after the selected point.
Run an annual large-scale exercise too: multiple sites, deleted accounts and the primary administrator unavailable. Measure decision time as well as transfer. The procedure should specify evidence, business validation, user communication, rollback and secure closure of temporary restore locations.
- Confirm every critical protection unit is actually creating recovery points.
- Test a recent point and the oldest point required by policy.
- Restore in place and to an alternate URL when both scenarios are planned.
- Compare measured RTO with approved RTO and correct gaps.
- Have the business owner validate files, not only the IT team.
- Document partial failures, missing permissions and unrestored dependencies.
The pragmatic conclusion
OneDrive and SharePoint provide excellent resiliency and several ways to correct a recent mistake. Simply using them does not create a complete backup strategy. A strategy exists only when scope, RPO, RTO, retention, administrative separation, loss scenarios and restore tests are defined and proven.
For a small organization, the right answer may be to harden and document native features, then back up only critical sites. For a regulated organization or one heavily dependent on Microsoft 365, full coverage with Microsoft 365 Backup, an independent product or a combination is often more coherent. The product follows the analysis; a tested restore remains the only proof.